Bug ID 723847: Disable flow if no protocol inspection profile is attached.

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP AFM(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1, 13.1.3.2, 13.1.3.3, 13.1.3.4, 13.1.3.5, 13.1.3.6, 13.1.4, 13.1.4.1, 13.1.5, 13.1.5.1, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1

Fixed In:
14.1.0

Opened: Jun 11, 2018

Severity: 3-Major

Symptoms

If protocol inspection profile is attached with no compliance checking or signatures enabled, the system still processes all the packets through the IPS library.

Impact

Potential performance degradation.

Conditions

-- Protocol inspection profile is defined and attached to a virtual server. -- The profile contains no inspections.

Workaround

If no inspections are needed, then remove the protocol inspection profile from the virtual server. Otherwise, there is no workaround.

Fix Information

If no inspections are enabled, there is no performance degradation when attaching the protocol-inspection profile.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips